3 ms·
Having authn stateless whether with JWTs or not is a bad idea. By extension refresh tokens are a bad idea. Doesn't mean JWTs are a bad idea, if used as a genera
by notnullorvoid 2y ago
Having authn stateless whether with JWTs or not is a bad idea. By extension refresh tokens are a bad idea. Doesn't mean JWTs are a bad idea, if used as a general auth token they are fine. Implementing revocation of JWTs also isn't very hard but you need somewhere to store the revocation state.
- tptacek 2y agoSorry, none of this is responsive to what I just wrote. I had a particular complaint about the critique I responded to, that's all.